Live data from Hacker News

Google no longer providing original URL in AMP for image search results

twitter.com

271–280 of 566 posts

Re: Google no longer providing original URL in AMP for image search results

#271

Earlier quoted context omitted.

Because its cover to allow them to subsume content and serve it solely from google.com, and deny the originating page any traffic or recognition, or swap it out transparently when they feel like it. This is literally already happening with the info sidebar, the reason signed exchanges matter is so they can throw up the smokescreen about how its cryptographically verified to come from the original page, so why are peo…

> swap it out transparently > cryptographically verified to come from the original page Elaborate.

The page results will be a tightly restricted iframe-esque window inside of google results (This is what the Chome "Portals" proposal is about).

There will be no obvious distinction between a search result and google's own website, even though the "portals" will be showing cryptographically signed content (which will almost certainly be in a super restricted AMP-esque format that denies sites much control besides what the text says)

If google swaps one result for another, 95% of users wont even notice.

Re: Google no longer providing original URL in AMP for image search results

#272

Earlier quoted context omitted.

Its deeply misleading to pretend stuff like signed exchanges and portals are purely about content distribution and security, and not control over said content being shifted to Google, and away from authors and other sites. Its a similar vein to how many of the objections to AMP were being white-washed with "its open source, if you have a problem with it why aren't you submitting a pull request??"

I'll bite: how does signed exchanges provide control to Google?

Does it behave different in different countries?

Will Google allow for example, Taiwan content in mainland China?

Is it like VPN/Proxy or has more knobs?

Re: Google no longer providing original URL in AMP for image search results

#273
post #89
post #51

Earlier quoted context omitted.

After they took away peoples' ability to MITM their own stuff by forcing HTTPS everywhere under the guise of privacy.

Not everyone joined the https party. The additional overhead on sites isn't justified for sites you don't even log into.

This is a common misconception. Https also prevents bad actors from injecting content into the page.

Re: Google no longer providing original URL in AMP for image search results

#275

Earlier quoted context omitted.

> swap it out transparently > cryptographically verified to come from the original page Elaborate.

The page results will be a tightly restricted iframe-esque window inside of google results (This is what the Chome "Portals" proposal is about). There will be no obvious distinction between a search result and google's own website, even though the "portals" will be showing cryptographically signed content (which will almost certainly be in a super restricted AMP-esque format that denies sites much control besides wha…

> If google swaps one result for another, 95% of users wont even notice.

Right so exactly the same way the search results page works today?

> The page results will be a tightly restricted iframe-esque window inside of google results

This is completely independent of AMP. Portals work for non-AMP content too.

> which will almost certainly be in a super restricted AMP-esque format that denies sites much control besides what the text says

So you're suggesting that Google will create a new, even more restricted than AMP protocol to be viewed on the search page?

Re: Google no longer providing original URL in AMP for image search results

#276
post #264

Earlier quoted context omitted.

As I understood signed exchanges, a correct implementation makes it impossible for the intermediary to inject, alter, replace, or otherwise swap out any part of the page without failing verification. This would mean the original server gets to do all the branding and get all the recognition and integrity in transit that its controllers might wish. I've clearly missed something. Can you help me?

AMP already heavily restricts what the original page is allowed to put inside, including things like ads, javascript and branding. You can be certain anything google implements around this proposal will have similar very tight restrictions.

That's definitely a scary thought! Can you share any details of what must be public plans to strip everything non-Google of branding? Surely there must be something out there beyond the IETF docs for the protocol, where I don't see any evil plans to Googlify everything in. If anything, it looks like a design intended to allow relaxing the restrictions imposed by AMP.

Perhaps I need to read them more closely.

Re: Google no longer providing original URL in AMP for image search results

#277
post #89

Earlier quoted context omitted.

Not everyone joined the https party. The additional overhead on sites isn't justified for sites you don't even log into.

The "additional overhead" argument against SSL hasn't held water for well over ten years, now.

Especially when you can just sit behind cloudflare and gett for free with very little work on your part.

Granted, you then have to trust cloudflare; but it seems like they have been good actors so far considering their privileged position delivering tons of content across the web.

Re: Google no longer providing original URL in AMP for image search results

#278

Earlier quoted context omitted.

Tell me about it. Our company moved to it and its been horrible with any third party application or marketing pixel. My boss tried to warn VPs of AMP being a nuclear option. Instead of fixing the website they rather put a bandaid over it.

> Our company moved to it and its been horrible with any third party application or marketing pixel. Isn't that part of the point though? 3rd party marketing and tracking pixels are NOT things that improve the experience or performance for the visitor.

In this case you are trading those all for Google's own.

Re: Google no longer providing original URL in AMP for image search results

#279

I have never liked AMP and I really don't like this. I also find myself wondering if this has any security implications. I mean if AMP effectively disguises the original URL could it not be used for phishing? To be clear I know very little about AMP and if this is the case Regardless it just adds complexity and makes it that much harder to teach people what is an acceptable URL when it comes to email links etc...

It uses Signed HTTP Exchanged. https://blog.amp.dev/2018/05/08/a-first-look-at-using-web-pa...

Thanks!

Re: Google no longer providing original URL in AMP for image search results

#280

I understand the objections to Google's actions--this is clearly a dick move which is terrible for both users and content creators--but I'm not understanding the AMP hate here. As a user, AMP is great. AMP is a better implementation of the open web than HTML is. It's a (usually) self-contained document that isn't tightly coupled to the server it came from. You can download an AMP document, render it, attach it to an…

> AMP is a better implementation of the open web than HTML is.

Except the results of AMP can be done without AMP. It just requires site owners to not put a bunch of crap on the site. Something that AMP requires you to do.

> You can download an AMP document, render it, etc., without having to log in or get tracked

Except for the fact that now only Google tracks you. Also, doable without AMP.

The hate from many isn't about being a website owner. It's about being a website user. When I click on a link of a website, I expect to go to that website. Not stay on Google's site.

Post reply on HN